Skip to content

Commit 2fba3ed

Browse files
committed
Ensure that all rules in RHEL ANSSI have references
1 parent 63855bf commit 2fba3ed

41 files changed

Lines changed: 85 additions & 1 deletion

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

controls/anssi.yml

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1422,7 +1422,7 @@ controls:
14221422
Another such service is winbind which is by default configured to connect securely to Samba domains.
14231423
Other relevant services are NIS and Hesiod. These should not be used.
14241424
status: pending
1425-
related_rules:
1425+
rules:
14261426
- no_nis_in_nsswitch
14271427

14281428
- id: R70
@@ -1453,6 +1453,7 @@ controls:
14531453
- service_chronyd_or_ntpd_enabled
14541454
- chronyd_specify_remote_server
14551455
- chronyd_configure_pool_and_server
1456+
- service_chronyd_enabled
14561457

14571458
# Derived from DAT-PA-012 R9
14581459
# The default remote loghost is logcollector.
@@ -1566,6 +1567,8 @@ controls:
15661567
- service_auditd_enabled
15671568
- package_audit_installed
15681569

1570+
- audit_rules_mac_modification_etc_selinux
1571+
15691572
- id: R74
15701573
title: Configuring the local messaging service
15711574
levels:

products/almalinux9/profiles/anssi_bp28_enhanced.profile

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -55,6 +55,10 @@ selections:
5555
- '!file_permissions_efi_user_cfg'
5656
- '!audit_rules_file_deletion_events_renameat2'
5757
- '!audit_rules_dac_modification_fchmodat2'
58+
- '!audit_rules_mac_modification_etc_selinux'
59+
- '!no_nis_in_nsswitch'
60+
- '!service_chronyd_enabled'
61+
5862
# disable R45: Enable AppArmor security profiles
5963
- '!apparmor_configured'
6064
- '!all_apparmor_profiles_enforced'

products/debian12/profiles/anssi_bp28_enhanced.profile

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -68,6 +68,10 @@ selections:
6868
- '!package_dracut-fips-aesni_installed'
6969
- '!audit_rules_file_deletion_events_renameat2'
7070
- '!audit_rules_dac_modification_fchmodat2'
71+
- '!audit_rules_mac_modification_etc_selinux'
72+
- '!no_nis_in_nsswitch'
73+
- '!service_chronyd_enabled'
74+
7175

7276
# The following rule is not applicable to Debian 12
7377
- '!logind_session_timeout'

products/debian13/profiles/anssi_bp28_enhanced.profile

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -75,3 +75,6 @@ selections:
7575

7676
# The following rule is not applicable to Debian 13
7777
- '!logind_session_timeout'
78+
- '!audit_rules_mac_modification_etc_selinux'
79+
- '!no_nis_in_nsswitch'
80+
- '!service_chronyd_enabled'

products/ol10/profiles/anssi_bp28_enhanced.profile

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -32,6 +32,7 @@ selections:
3232
- '!sudo_add_umask'
3333
- '!cracklib_accounts_password_pam_minlen'
3434
- '!cracklib_accounts_password_pam_dcredit'
35+
- '!no_nis_in_nsswitch'
3536
# authselect is enabled by default
3637
- '!enable_authselect'
3738
# this rule is not automated anymore

products/ol10/profiles/anssi_bp28_high.profile

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -36,6 +36,7 @@ selections:
3636
- '!sudo_add_umask'
3737
- '!cracklib_accounts_password_pam_minlen'
3838
- '!cracklib_accounts_password_pam_dcredit'
39+
- '!no_nis_in_nsswitch'
3940
# authselect is enabled by default
4041
- '!enable_authselect'
4142
# this rule is not automated anymore

products/ol10/profiles/anssi_bp28_intermediary.profile

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -30,6 +30,7 @@ selections:
3030
- '!ensure_redhat_gpgkey_installed'
3131
- '!ensure_almalinux_gpgkey_installed'
3232
- '!sudo_add_umask'
33+
- '!no_nis_in_nsswitch'
3334
# authselect is enabled by default
3435
- '!enable_authselect'
3536
# this rule is not automated anymore

products/ol10/profiles/anssi_bp28_minimal.profile

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -30,6 +30,7 @@ selections:
3030
- '!ensure_redhat_gpgkey_installed'
3131
- '!ensure_almalinux_gpgkey_installed'
3232
- '!security_patches_up_to_date'
33+
- '!no_nis_in_nsswitch'
3334
# authselect is enabled by default
3435
- '!enable_authselect'
3536
# these packages do not exist in ol10 (R62)

products/ol7/profiles/anssi_nt28_enhanced.profile

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -50,3 +50,6 @@ selections:
5050
- '!package_kea_removed'
5151
- '!audit_rules_file_deletion_events_renameat2'
5252
- '!audit_rules_dac_modification_fchmodat2'
53+
- '!no_nis_in_nsswitch'
54+
- '!audit_rules_mac_modification_etc_selinux'
55+
- '!service_chronyd_enabled'

products/ol7/profiles/anssi_nt28_high.profile

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -76,3 +76,4 @@ selections:
7676
- '!package_kea_removed'
7777
- '!audit_rules_file_deletion_events_renameat2'
7878
- '!audit_rules_dac_modification_fchmodat2'
79+
- '!no_nis_in_nsswitch'

0 commit comments

Comments
 (0)